NA - CVE-2025-7729 - A vulnerability classified as problematic was...
A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file usersProfiles.shtm. The manipulation of the...
Critical - CVE-2025-7712 - The Madara - Core plugin for WordPress is...
The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_delete_zip() function in all versions up to, and including,...
High - CVE-2025-7735 - The Hospital Information System developed by...
The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
NA - CVE-2025-4302 - The Stop User Enumeration WordPress plugin...
The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.
NA - CVE-2025-3415 - Grafana is an open-source platform for...
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission....
NA - CVE-2025-5344 - Bluebird devices contain a pre-loaded kiosk...
Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind...
NA - CVE-2025-5345 - Bluebird devices contain a pre-loaded file...
Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can...
NA - CVE-2025-5346 - Bluebird devices contain a pre-loaded barcode...
Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can...
NA - CVE-2025-1713 - When setting up interrupt remapping for legacy...
When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of a lock, is done in...